JPEG Processing BOF Proof Of Concept

From: GulfTech Security (security_at_gulftech.org)
Date: 09/16/04

  • Next message: NGSSoftware Insight Security Research: "Microsoft WordPerfect 5.x Converter Heap Overflow"
    To: <bugtraq@securityfocus.com>
    Date: Thu, 16 Sep 2004 12:53:15 -0500
    
    
    

    About a year ago I came across this same issue. I came across it while
    messing with Solar Designer's old Netscape JPEG bug. So, in short the same
    issue applies to WinXP it seems. I showed the bug to a few people (even
    contacted Microsoft, but got no reply), but neither them nor myself ever got
    around to figuring it out. Nick DeBaggis and eEye did a good job of figuring
    this very dangerous issue out :)

    Anyway, the point to this post is to release the POC I just put together
    using the findings that I have been sitting on for quite some time. As I
    said before, I never fully understood exactly what was going on, so this POC
    doesn't execute code or anything, but it will crash any WindowsXP machine
    that has not been patched from this flaw.

    If you cannot access the attached file, you may download the POC here

    http://www.gulftech.org/?node=downloads

    BTW: There was a BugTraq (or some other sec mailing list) post from over a
    year ago that talks about the Netscape JPEG issue crashing the WindowsXP
    Shell. I remember seeing them when I first started looking into this issue,
    but do not have links right off hand. Maybe someone else reading this does?

    
    



  • Next message: NGSSoftware Insight Security Research: "Microsoft WordPerfect 5.x Converter Heap Overflow"
  • Quantcast